Cloud Security Architect
Openkyber
Job Role : Aws Cloud Security Engineer Location : Boston, MA, Arlington, VA, Atlanta, GA,:Austin, TX, Chicago, IL, Cleveland, OH: Experience: 10 Years Skills: This Senior Consultant role modernizes legacy workloads into cloud-native, resilient and observable AWS platforms. The consultant is expected to operate as an embedded AWS SME, provide hands-on implementation support, and create audit-ready technical documentation aligned to regulated Financial Services delivery expectations. Role Scope & Key Responsibilities:
- Multi-Account Governance (WS-2): Design AWS Organizations landing zone with OU structure, Service Control Policies (SCPs), centralized logging (CloudTrail, VPC Flow Logs, AWS Config), and automated account vending for Security Lab foundation
- Isolated Recovery Environment (WS-3): Architect IRE account with WORM vault locking (S3 Object Lock/Backup Vault Lock), cross-account/cross-region backup (3-2-1 strategy), AWS KMS CMKs, CyberArk break-glass integration, Amazon Macie data classification, AWS Network Firewall, Transit Gateway route isolation, and recovery orchestration
- Clean Room Forensics: Design forensic investigation environment with network isolation, immutable evidence storage, and controlled access patterns
- Security Lab Infrastructure: Establish Amazon EKS baseline and lab environment for testing security capabilities, threat simulation, and vulnerability assessments
- Compliance & Audit: Design AWS Backup Audit Manager compliance framework, Route 53 DNS isolation, and hardened compute baselines (AMI/container hardening)
- Documentation & Implementation: Author IRE & Clean Room Architecture & Design Document, Security Lab Architecture Document, lab operations guide, and account vending admin procedures
- Security Agent Infrastructure (WS-1): Design and support AWS Security Agent cloud infrastructure implementation Secrets Management: Implement AWS Secrets Manager/Parameter Store integration with CyberArk for break-glass scenarios
- Multi-Account Landing Zone Architecture with OU/SCP design
- IRE & Clean Room Architecture & Design Document
- Security Lab Architecture Document
- Backup Audit Manager compliance framework
- Hardened compute baselines (AMIs, EKS node configurations)
- Account vending automation and admin procedures Recovery orchestration runbooks
- AWS Organizations: OU structure design, SCP policies, consolidated billing, cross-account IAM strategies
- AWS Control Tower: Landing zone automation, guardrails, Account Factory customization
- AWS Service Catalog: Automated account vending, standardized resource provisioning
- AWS Resource Access Manager (RAM): Cross-account resource sharing for Transit Gateway, Route 53 Resolver
- AWS IAM: Advanced policies, permission boundaries, IRSA (IAM Roles for Service Accounts), cross-account roles, break-glass access patterns
- AWS KMS: Customer Managed Keys (CMKs), key policies, cross-account/cross-region key grants, envelope encryption
- AWS Secrets Manager: Secret rotation, CyberArk integration, cross-account secret access
- Amazon Macie: Sensitive data discovery, S3 bucket classification, compliance reporting
- AWS Security Hub: Centralized security findings, compliance standards (CIS, PCI-DSS)
- AWS GuardDuty: Threat detection, malware protection, runtime monitoring
- AWS Network Firewall: Stateful/stateless rules, intrusion prevention, domain filtering
- AWS WAF: Web application protection, managed rule groups
- AWS Backup: Centralized backup management, WORM vault locking (Vault Lock), cross-account/cross-region backup, 3-2-1 backup strategy
- AWS Backup Audit Manager: Compliance framework design, backup policy enforcement, audit reporting
- Amazon S3: Object Lock (WORM compliance), versioning, cross-region replication, Glacier Vault Lock
- AWS Elastic Disaster Recovery (DRS): Continuous replication, recovery orchestration, failover testing
- AWS CloudTrail: Multi-account trail design, log file validation, S3/CloudWatch Logs integration, event history analysis
- Amazon CloudWatch: Centralized logging, log aggregation, metric filters, alarms, dashboards
- VPC Flow Logs: Network traffic analysis, security group validation, threat detection
- AWS Config: Configuration compliance, resource inventory, change tracking, conformance packs
- Amazon VPC: Advanced networking, security groups, NACLs, VPC peering, PrivateLink
- AWS Transit Gateway: Hub-and-spoke architecture, route table isolation, network segmentation
- Amazon Route 53: DNS isolation, private hosted zones, DNSSEC, resolver rules
- AWS PrivateLink: Service endpoint isolation, cross-account connectivity without internet exposure
- Amazon EKS: Cluster hardening, pod security policies/standards, IRSA, network policies, secrets encryption, runtime security
- Amazon ECR: Image scanning, vulnerability assessment, immutable tags, lifecycle policies
- AWS Systems Manager: Patch Manager, Session Manager (bastion replacement), Parameter Store, hardened AMI automation
- Amazon EC2: Hardened AMI creation, IMDSv2 enforcement, instance metadata security, EBS encryption
- Amazon Detective: Security investigation, graph-based analysis, threat hunting
- AWS Step Functions: Recovery orchestration workflows, automated incident response
- Amazon EventBridge: Event-driven security automation, cross-account event routing
- AWS Lambda: Automated remediation, forensic data collection, snapshot automation
- AWS CloudFormation: StackSets for multi-account deployments, nested stacks, drift detection
- AWS CDK: Programmatic infrastructure definition, construct libraries for security patterns
- AWS Service Catalog: Self-service account vending, compliance-approved resource templates
- AWS Cost Explorer: Cost allocation tags, backup storage optimization
- AWS Budgets: Cost alerts, anomaly detection
- AWS Trusted Advisor: Security and cost optimization recommendations Financial Services & Industry Skills
- Large regulated financial-services delivery with formal change-control, audit and risk governance
- Operational resilience expectations including RTO/RPO, multi-region DR and evidence for audit review
- Awareness of applicable controls and regulations such as DORA, NIST CSF 2.0, PCI DSS, SEC cyber rules, RegSCI and SIFMU/FMI expectations where relevant
- Ability to create Tech Risk-ready documentation including ADRs, runbooks, design docs, threat models and validation evidence
- Clear communication with client engineering, security, SRE, data and platform stakeholders as an embedded SME
- AWS Certified Solutions Architect - Associate / Professional
- AWS Certified Developer - Associate
- AWS Certified DevOps Engineer - Professional preferred
For applications and inquiries, contact:View email address on us.fitly.work
$163.9k - $235.55k
...you. Job Description We are looking for a Principal AI Security Architect to join UKG's Application Security Architecture team. This is... ...that can be consistently applied across multi-tenant SaaS and cloud environments. Design and build reusable security harnesses...SuggestedWork experience placementLocal areaRemote work$122.6k
...CDM Smith is seeking a Senior Enterprise Architect to join our Corporate Business Technology... ...in alignment with our Microsoft-centric, cloud-first IT strategy. The Senior Enterprise... ...connect business capabilities with scalable, secure, and integrated technology solutions....SuggestedWork experience placementH1bRemote work- ...Azure Cloud Architect Location : Remote W2 ONLY Experience : 13+ Position Overview We are looking for an experienced Azure Cloud Architect... ...ideal candidate will be responsible for designing scalable, secure, resilient Azure solutions and supporting modern cloud-native...SuggestedRemote work
$112.5k - $202.5k
...Do you like building solutions to help improve the security of the company? Do you want to collaborate with industry-leading security... ...scenes. We provide the world's most distributed platform from Cloud to Edge to help the giants of the digital world work faster and...SuggestedWork experience placementWork at officeWorldwide$98.9k
...What you can expect The Security Engineer is responsible for security design and reviews across our products and services. The ideal... ...enhancements. This is a unique opportunity to work with cutting-edge cloud and security technologies while making a direct impact on Zoom’...SuggestedWork at officeRemote work$40k
...federal partner supporting mission-critical programs across national security, defense, and public service delivery. Our work focuses on... ...requires familiarity with security operations processes, cloud and infrastructure fundamentals, and the ability to follow established...Contract workRemote work- ...stakeholders across technical and business domains. Experience Requirements: Strong hands-on DevOps experience. Expertise with Azure Cloud Services, Azure Kubernetes Service (AKS), and Terraform or Infrastructure as Code. Strong scripting skills such as Python and...Hourly payContract workLocal areaRemote work
$106.3k - $234.6k
...Job Description The Oracle Cloud Infrastructure (OCI) team can provide you the opportunity to build and operate a suite of massive... ...of the world’s biggest challenges. As a Principal Hardware Security Engineer you will be involved in ensuring that the compute hardware...Temporary workFlexible hours- ...a Senior Staff DevOps Engineer focused on Terraform and Google Cloud Platform. The engineer will enable GCP infrastructure for AI and... ...analytics workloads. Collect manufacturing process data and enable secure movement into GCP services including BigQuery, Dataplex,...Hourly payContract workLocal areaRemote work
$120k - $180k
...or yours. Job Summary The Senior Cloud Engineer will play a leadership role on... ...work closely with development, DevOps, and security teams to deliver reliable, scalable, and... ...reliability, and cost optimization. Architect and develop reusable IaC modules and frameworks...Full timeRemote workWorldwideHome officeFlexible hours- ...metal, virtualized systems, containerized platforms, and major cloud providers. Rather than operating within a fixed platform, you... ...on top of your work. Systems researchers and senior architects who bring deep domain expertise across distributed systems, query...Permanent employmentWork at officeFlexible hours
$92.5k - $209.5k
...working in ambiguity, shipping iteratively, and reasoning about topology — not just features. Nice to have • Prior work on multi-cloud or hybrid deployments. • Exposure to QEC, quantum-classical hybrid workloads, or scientific computing. • Open-source...Temporary workFlexible hours$94.1k - $150k
...ensuring reliability, scalability, and security. This role supports application deployment... ...virtualization, containerization, and cloud platforms ~ Excellent problem-solving... ...Kubernetes Administrator (CKA) AWS Solutions Architect or Azure Solutions Architect...Contract workWork at office$92.5k - $209.5k
...Job Description Job Description The Oracle Cloud Infrastructure team is building and operating a broad set of highly available,... ...the internal platforms that enable OCI teams to build, validate, secure, and release software safely at cloud scale. At OCI, engineers have...Temporary workFixed term contractFlexible hours$264k - $363k
...driving business growth within the region.Partner with the core sales team to align customer strategies and engagements with Cortex and Cloud business objectives.Take full ownership of leading strategic sales campaigns, sales forecasting, utilizing in-depth knowledge of...Full timeRemote workVisa sponsorshipWork visa$104.5k - $234.6k
...future enhancements). Practices and Standards Compliance - Security and Compliance: Collaborates with the team and externally to... ...Qualifications Hands-on experience developing services on a public cloud platform (e.g., AWS, Azure, Oracle) Experience and...Temporary workFlexible hoursShift work$116.4k - $204.1k
...for a Lead Product Software Engineer - Cloud Operations to join I nnovateHub , our... ...infrastructure-as-code modules that are secure, repeatable, and compliant with SOC 2 and... ...Administrator) or AZ-305 (Azure Solutions Architect) certification is highly desired - our team...Work at office$160.2k - $246.3k
...Role : We're looking for a seasoned Security Software Engineer to join our IAM team (... ...Identity Access Management) to help develop, architect and advance our suite of applications... ...security into CI/CD pipelines and cloud-native environments Collaborate with...Full timeFor contractorsLocal areaRemote workWork from homeRelocation packageFlexible hours$186.07k - $218.9k
...customer support and compliance automation, from LLM orchestration through production deployment and monitoring. Build scalable, secure backend infrastructure in Python and Golang that serves AI workloads, including model integration pipelines, guardrails, grounding...Local area$180.37k - $212.2k
Ready to do the most impactful work of your career? AtCoinbase, we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your...Local area$264k - $363k
...business growth within the region. Partner with the core sales team to align customer strategies and engagements with Cortex and Cloud business objectives. Take full ownership of leading strategic sales campaigns, sales forecasting, utilizing in-depth knowledge of...Remote work$40 per hour
A cybersecurity company is seeking experienced professionals to evaluate AI-generated security content and contribute to building reliable AI tools. This remote role offers flexibility to choose projects and work hours, with pay starting at $40+ per hour. Ideal candidates...Hourly payRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cloud Security Architect. Be the first to apply!


